Microsoft Sentinel
Cloud and workloads

Microsoft Sentinel SIEM and platform solution overview

In brief

A new overview explains the differences between SIEM and platform solutions, including their purposes, audiences, content types, foundations, data scopes, tooling, and publishing flows. It also links to guidance for building and publishing SIEM solutions.

What Defender admins need to know

Administrators evaluating partner integrations can use the overview to identify the appropriate solution path and find relevant implementation guidance. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

new file mode 100644

title: Microsoft Sentinel SIEM and platform solution overview description: Learn how Microsoft Sentinel SIEM and platform solutions differ, find the right build and publish guidance for each path, and get support when you need it. author: EdB-MSFT ms.author: edbaynash ms.service: microsoft-sentinel ms.topic: concept-article ms.custom: msecd-doc-authoring-101 ms.date: 06/28/2026 ai-usage: ai-assisted #customer intent: As an ISV partner, I want to understand Microsoft Sentinel SIEM and platform solution paths so that I can find the right build and publish guidance and get support when I need it.

Microsoft Sentinel SIEM and platform solution overview

Microsoft Sentinel ISV solutions are partner-built integrations and content that extend Microsoft Sentinel for customer scenarios. As an independent software vendor (ISV), you package your product's connectors, detections, automation, and analytics experiences into a solution that customers discover, install, and use directly inside Microsoft Sentinel. A well-built solution lets customers onboard your product in minutes instead of building integrations themselves, and it gives your product a presence in the marketplaces that security teams already use.

You can build two solution types, and they target different parts of the Microsoft Sentinel experience:

  • SIEM solutions deliver detection, investigation, and automated response content for Security Operations Center (SOC) teams. They bring your product's logs into Microsoft Sentinel and turn that data into ready-to-use analytics rules, hunting queries, workbooks, playbooks, and parsers.

  • Platform solutions deliver large-scale data analysis and AI-driven experiences built on the Microsoft Sentinel data lake and graph. They include Security Copilot agents, Model Context Protocol (MCP) tools, custom graphs, and notebook jobs for scenarios that analyze large volumes of security data.

The two paths use different content types, build tooling, quality requirements, and publishing flows. Understanding the differences early helps you choose the right content path, scope your work accurately, and avoid rework before you start development and publishing. The rest of this article compares the two solution types and links to the detailed build and publish guidance for each.

Compare SIEM and platform solutions

The two solution types serve different customer needs, use different content, and publish through different stores.

SIEM solutionsPlatform solutions
PurposeDetection, investigation, and automated response for Security Operations Center (SOC) teamsLarge-scale data analysis and AI-driven scenarios that use the Microsoft Sentinel data lake and graph
Primary audienceSOC analysts, threat hunters, and detection engineersSecurity data scientists, threat researchers, and teams building AI-assisted investigations
Typical contentData connectors, analytics rules, hunting queries, summary rules, workbooks, playbooks, and Advanced Security Information Model (ASIM) parsersSecurity Copilot agents, Model Context Protocol (MCP) tools, custom graphs, and notebook jobs
FoundationMicrosoft Sentinel workspace and content hubMicrosoft Sentinel data lake and graph
Data scopeReal-time and near-real-time analytics on workspace tablesLarge historical and high-volume datasets stored in the data lake
Build toolingAI connector builder agent, Codeless Connector Framework (CCF), YAML content templates, and the V3 solution packaging toolKQL jobs, VS Code notebook and graph development tools, and the platform packaging flow

If you're not sure which content your scenario needs, start with Decide which components to include in your solution for SIEM solutions .

Build and publish SIEM solutions

SIEM solutions focus on detections, investigations, and automation for SOC teams. Use the following articles to plan, build content, publish, and maintain a SIEM solution.

Plan and understand the lifecycle

Build data connectors

Build detection, hunting, and visualization content

Publish and maintain

Troubleshoot solutions

If you run into data ingestion, analytics, packaging, or agent integration issues while building or publishing either solution type, see Troubleshoot solutions in Microsoft Sentinel.

Contact App Assure

If you're an independent software vendor (ISV) and need support when building a Microsoft Sentinel integration by using the Microsoft Sentinel Codeless Connector Framework, the Microsoft App Assure team might be able to assist. To engage the App Assure team, send an email to [email protected] for assistance. \ No newline at end of file